Defense in depth. Sovereign data residency. Transparent compliance. Everything an enterprise procurement team needs to do their job. In one place.
Security is not one feature. It is the way the platform is layered. Each layer protects against a different class of threat. A failure at one layer is contained by the next.
Azure App Service with TLS 1.2+, HSTS (365-day with preload), and CORS controls. All traffic encrypted in transit.
Multi-factor authentication, OAuth 2.0, SSO via Google Workspace and Microsoft Entra ID. SHA-256 hashed API keys with IP whitelisting.
Role-based access control with granular permissions on every entity. Query-level tenant isolation. Architecturally impossible cross-tenant access.
Four-layer input validation. Comprehensive security headers. OWASP Top 10 protections enforced at the framework level.
AES-256 encryption at rest (Azure Transparent Data Encryption). TLS in transit. Azure Key Vault HSM for all secrets. BCrypt password hashing.
Immutable audit logs. Security event alerting. Account lockout and rate limiting against credential stuffing.
Customer data lives in Microsoft Azure's Canada region. And stays there. This is not a configurable preference; it is the deployment model.
Some frameworks are statutory in Bermuda. Some are inherited from Azure. Some are voluntary commitments we hold ourselves to.
Bermuda Personal Information Protection Act. Data protection, 72-hour breach notification, consent management.
Full compliance with calculations, filings, classifications, and quarter-end submissions.
Statutory leave entitlements, employment record retention (7-year), maternity/paternity provisions.
Comprehensive protections against all OWASP Top 10 threats, enforced at the framework level.
In progress. Policy framework established; audit underway.
SOC 1/2/3, ISO 27001/27017/27018, FedRAMP, HIPAA. Microsoft Azure is our infrastructure provider.
Backed by Azure App Service SLA. Graceful degradation means non-critical features (AI, analytics) degrade independently. Core payroll processing is always available.
We are transparent about every vendor that touches your data. Any change is communicated in advance.
| Service | Purpose | Location | Data scope | |
|---|---|---|---|---|
| Microsoft Azure | Infrastructure, database, app hosting, AI inference | Canada | All customer data | |
| Stripe | Payment processing (subscriptions) | US / global | Billing data only | |
| Azure OpenAI | AI inference for Patty, Iris, Maren | AI inference for Patty and Iris | Regional (Canada preferred) | Query payloads, no PII in summaries |
| Anthropic | AI inference fallback & advanced reasoning | US | Query payloads, no PII in summaries |
Maren can route the request to the right person and turn it around within one business day.
Reach the security team directly. Most requests are turned around within one business day.
Maren has been trained on this trust center. Ask her anything, and she will either answer or get you to someone who can.
Reach the security team. We will get back to you within one business day.
In production this would play.